[IMAGE: https://images.hive.blog/DQmdnWq4iiWpeEmD8kZ9zpiuEFmQN7SqQ6uhatGhRzRoMLV/image.png]
Everyone loves Hive Keychain, it is the only way to use many of the Hive Dapps and still feel safe.
One thing that has always concerned me of Hive Keychain is it has never been audited by a third party. There are many situations that may arise that put users of the Hive Keychain extension at risk. Some of these don't even involve the developers of the extension themselves.
Hive Keychain relies on a lot of trust that it is safe and remains safe. Most users store their posting, memo, and even active keys in Hive Keychain.
I have consulted a few crypto software auditing companies to get a rough idea what it would cost to audit Hive Keychain for secuity issues and it isn't cheap. When you start trying to audit every release, it gets even more prohibitively expensive.
The cheapest I have found is $24,000 for an initial audit, with a 10% discount on future audits as code changes. That's another $21,600 for each release of Hive Keychain.
This proposal would provide one year of auditing of Hive Keychain, which I would do personally. I have first hand knowledge of the Hive Blockchain and experience in information security (it is in fact my career).
My offer
What I am offering is an initial and complete audit on the Hive Keychain extension on both Google and Firefox web stores. Once this is complete, I will monitor all future updates of the extension and audit the changes for potential issues. I will decompile and audit the actual released version of the extension to ensure I am looking at the code actually deployed in case for whatever reason it differs from the Github repository.
This audit is security focused only and will not look for bugs or optimizations.
I would ask for 61 HBD/day for 365 days, renewed yearly. To submit this proposal will cost 1 HBD/day beyond 60 days, the additional 1 HBD/day would be used to reimburse this cost. 60 HBD/day would be compensation for my time throughout the year. This would result in a total of 21,900 HBD, a few thousand under the lowest offer to only audit the extension once. I will provide that as well as future reviews in a reasonable time after new releases.
I believe it is critical a third party reviews Hive Keychain (me or otherwise) not only once but on an ongoing basis to ensure it remains a safe option for Hive users. This proposal would offer a independent and ongoing audit of the most critical critical piece of software used by most Hive users on a daily basis.
There is currently no active proposal for this audit, but if the community feels this is something they would support, I will draft it up and update this post.
Posted Using LeoFinance Beta
> Who are you, anyway, and why should we care?
I am Marky. I've built a reputation here, that I believe speaks for itself, love or hate it.
> Why would the community support and trust your audit specifically?
Someone should do it, it has been left undone for far too long. It should be someone with no ties or incentive from the original team. I have neither.
> What is the state of the Hive Keychain code?
It is open source but unreviewed (as far as I know).
In my opinion, it is highly used and if something were to go wrong could potentially cause catastophic results.
@urun | Oct. 14, 2021, 8:22 a.m. | Votes: 7 | [
VOTE ]
Good proposal.
Some questions:
Does it include the mobile version? ( i don't use, but i expect some do).
Is the reference worth something? So can we tell it is reviewed and safu? Like the Defi protocols?
And IMO Keychain was simple in most parts ( from key storage). I think transactions and things like that can be easier manipulated. But keys should be safe because is open source and on the browser (local) pretty decentral.
If a website can access it, it must be also encrypted. I think the most easy scam is, you post something and the website sends a transfer massage. Missclick = lost funds (if active is in it).
And does it really help? I ask because of updates.
Today safe, it doesn't mean after someone accesses Mozilla or google account, it can not change.
Most Apps on those stores become problems ( from security) after the owner changes/updates.
Posted Using LeoFinance Beta
I would not support such a proposal as you have presented it to us.
You refer to "external prices" to support your valuation but do not provide any information about them (company names, offers, ...). It would be nice to know more about the proposals you received.
You also do not provide an estimate on the volume of work that such an audit represents. It might be good to know how often Keychain undergoes updates, either to adapt to the change of the blockchain code (hardfork) or to integrate new functionalities. Have you ever inquired about this?
More important is the timing of your audit. Did you know Keychain is under heavy refactoring? It would be quite wasteful work to do an audit before this major overhaul has been done and released.
I'm also surprised you do not plan to audit Keychain Mobile and wrote in a reply you do not know if it is open-source. Yet it is easy to find (https://github.com/stoodkev/hive-keychain-mobile) as it is the last and most updated repository from @stoodkev on Github.
It would be a shame to do things halfway. While I understand that it is difficult to certify that the executed code of an application is the same as that of the repository, it would still be good to ensure that the available code is safe.
Add to this that @stoodkev does not hesitate to present himself publicly, which is not your case, and him having as good a reputation as yours, we can have good reason to trust him that he doesn't cheat when he pushes the app to the stores.
Finally, I would find it more appropriate to make a proposal to fund the initial audit once it is done and to proceed in the same way when there are updates to Keychain. If the quality of the first one is there, there should be no problem approving the following ones.
@klevn | Oct. 15, 2021, 3 p.m. | Votes: 2 | [
VOTE ]
i found him to be someone that refused to debate
don't care if you believe it or not, i have come to see
the earth is indeed flat, markymark made a post decrying the opposite and then didn't engage my comment
https://hive.blog/science/@klevn/qjf4zz
those with closed minds often have an agenda
and they aren't sharing, and that is not secure
i also suspect he got steemflagrewards to downvote me, as it was received almost immediately upon posting
who runs them if he doesn't and why was this post downvoted by them? did i say something offense other than to ask for proof?
I think you think you some kind of smart person.
Picture shows what you just purported. The level LOL
Emu with its head in the sand. Ever heard of gravity? Newton? Apple falling from a tree? The gravity equation? Physics?
It's ok, you don't want to admit you are wrong, probably because you have invested so much of your time and effort. Along with purchasing what ever quack pot ideas these snake salesmen have sold you.
Science...
But then again I know what you really want. A free ticket up into space by arguing your point until someone wants to shut your mouth with the truth by paying for your fare up there.
Here so you can understand what it is that is level. Am sure you won't watch because it will just prove you wrong.
https://youtu.be/y8MboQzXO1o?t=289
@klevn | Oct. 29, 2021, 1:42 p.m. | Votes: 0 | [
VOTE ]
>Ever heard of gravity?
yup, and it is unprovable garbage
>Newton?
yup
>Apple falling from a tree?
ever seen an apple fall in water? what happened to your gravity?
>The gravity equation?
equation of an apparent physical phenomena .. labeled to be something beyond boyancy with zero proof
>Physics?
passed college level physics
>It's ok, you don't want to admit you are wrong ... Science...
science is observation of physical reality. you are viewing reality thru a corporate lens that is profitable for many but actually fails to stand up to reality tests. right now there is a 70% failure to reproduce a scientific study .. your scientific world has walked away from reality around the time of Tesla .. in which he stating basically .. we have gone further and further from reality into a theoretical world.
>A free ticket up into space by arguing your point
no, i want to stop wasting BILLIONS everyday what returns nothing.
nasa has more cgi computers than hollywood. nasa uses more helium than pretty much anyone.
why? weather ballooons and cgi are what they do
that, and pay to people lie.. and force people that give conclusive evidence to go away
https://earth.nullschool.net/ <- this used to have a flat earth map that when viewed on a live map of live earth made it clear the reality made more sense as you saw the flow of consentric of temperature and wind around a north pole. THEY REMOVED THIS FROM THE WEBSITE .. DELETED IT FROM THE GITHUB .. and broke their own project .. yet never said why ..
i put the project back together and proved it was NOT accidentally broken.. but purposedly broken ..
https://www.youtube.com/watch?v=FFTDaLbYbPE
archaic, false beliefs require removal, destruction of truth to survive.. and I have witnessed numerous take downs of flat earth ideas .. not by truth.. but censorship without reason.
@klevn | Oct. 30, 2021, 3:18 p.m. | Votes: 0 | [
VOTE ]
yet I point at mountains that can be seen from hundreds of miles .. all the way down to the base
the fact you don't understand the implications of this is not a fault in my presentation
but your inability to understand is directly related to your belief you are correct in the face of facts that defy your reality .
yet you literally have nothing that 'proves' your point..
you have nasa (big gov)
you have space x (big corp)
i have videos of bubbles in space
i have pictures of prop rocks present ON THE MOON from the official photography
you believe a man stepped onto soft moon dust after have landed using jet propulsion landing system .. that was only tested once and crashed during that test
literally nothing about your reality stands up to scrutiny.
still laughing at the suez canal picture you presented. literally stated the canal was 100% level and you present a picture with a curve ..
@klevn | Oct. 31, 2021, 10:20 a.m. | Votes: 0 | [
VOTE ]
how many feet of concrete is require to make perfect vacuum?
10 feet, of reinforced concrete
and we have people going up in tin cans, thru the thermal sphere
the hilariousness of this is beyond funny, and you either understand it fully and are ignoring it .. or ignorant and blindly following lies given to you
the one time we tested a 'space suit' by putting the guy in the vacuum chamber .. the water on his tongue started to boil and he passed out
http://www.spacesafetymagazine.com/aerospace-engineering/space-suit-design/early-spacesuit-vacuum-test-wrong/
this is the first and last time they ever tested a suit in a vacuum .. how can this be?
@klevn | Oct. 31, 2021, 10:39 a.m. | Votes: 0 | [
VOTE ]
haha holyshit they have all been replaced on youtube with flat earth denial videos.
https://hive.blog/video/@klevn/re-uvas-re-klevn-re-uvas-re-klevn-re-uvas-re-klevn-re-uvas-re-klevn-re-uvas-re-klevn-re-uvas-re-klevn-re-uvas-re-klevn-re-terenceplizga-re-einarkuusk-0bl2cofu-20180123t233306790z
https://hive.blog/video/@klevn/re-uvas-re-klevn-re-uvas-re-klevn-re-uvas-re-klevn-re-uvas-re-klevn-re-uvas-re-klevn-re-uvas-re-klevn-re-uvas-re-klevn-re-uvas-re-klevn-re-terenceplizga-re-einarkuusk-0bl2cofu-20180124t140414392z
i had posted them here, and now they are all actually ball earth videos. literally changed them.
you can clearly see by the follow-up comments that they are in fact what I say they are or the guy i was talking to would have laughed. (he was alot like you)
whatever, it is going to get harder and harder to prove what multi-trillion dollars wants to hide
i might have saved them, I will look later
I would gladly support auditing Keychain, we are usually posting very frequent updates, which would make repeated external audits very expensive.
After reading the comments section, I do have a few remarks and questions though:
1) The project started small and grew fast, and that led me to decide to start a refactor a few months back, that will hopefully be ready by year end. We are rewriting the entire code base using React.js, is it a library you are comfortable with? Also, this means that depending on when you start, you'd have to review the entire code twice.
2) Yes, Keychain Mobile is 100% open source: https://github.com/stoodkev/hive-keychain-mobile
3) I would also like to see the question of your credentials being addressed. Not that I don't trust you have to skills to do this, as you put it, you've built a reputation here. However our ecosystem is growing faster than ever and your reputation won't mean much to new comers. Could you include a list of relevant projects that you've reviewed/audited in your proposal?